CyberGuard legal
Privacy Policy
Effective 2026-07-17 · Last updated 2026-07-17 · Version 2026.07.17-draft
Introduction
This policy describes how [LEGAL BUSINESS NAME] collects, processes, stores, protects, and deletes information when users access CyberGuard in [COUNTRY].
Contact: [CONTACT EMAIL]. Privacy contact: [PRIVACY EMAIL].
Information Collected
CyberGuard may collect account information, email addresses, authentication identifiers, workspace membership, user settings, uploaded logs and evidence, generated findings, AI prompts and responses, reports, audit events, diagnostics, browser/device information, approximate network information, and support communications.
Data may be supplied directly by the user, generated by CyberGuard, or collected automatically for security and reliability.
Uploaded Security Data
Uploaded evidence may include IP addresses, usernames, hostnames, domains, URLs, file hashes, process names, event identifiers, system paths, authentication events, firewall events, VPN events, proxy records, security alerts, and vulnerability findings. Users are responsible for ensuring they are authorized to upload and process this data.
Whether Files Leave the User's Computer
Uploaded files leave the user's browser and are transmitted to CyberGuard's hosted application environment for analysis and storage.
AI analysis is performed using CyberGuard's self-hosted AI infrastructure. Uploaded evidence and prompts are not sent to a third-party generative AI provider unless a feature explicitly states otherwise.
AI Processing
CyberGuard creates prompts from relevant evidence, findings, and user questions. Uploaded evidence may be included in prompts when needed for AI assistance.
Prompt retention: 30 days. Response retention: 30 days. Customer security data is not used to train public or shared AI models.
Purposes
CyberGuard processes data to provide the service, authenticate users, analyze security evidence, generate reports, maintain workspaces, prevent abuse, protect accounts, diagnose technical issues, meet legal obligations, respond to support requests, and improve reliability and usability. Legal bases may vary by jurisdiction and require legal review.
Who Can Access Uploaded Evidence
Evidence may be accessed by the uploading user, authorized workspace members, authorized CyberGuard administrators when necessary for support, abuse investigation, security, or legal compliance, automated processing services, and approved infrastructure providers. Support personnel should not access customer evidence unless necessary and authorized.
Retention
See the Data Retention Policy. Summary: raw uploads 30 days, parsed events 90 days, findings 180 days, reports 180 days, audit logs 365 days.
Security
CyberGuard uses controls such as encryption in transit, authentication, access controls, Row Level Security, private storage, audit logging, role-based permissions, backups, monitoring, and data minimization. No system can be guaranteed completely secure.
User Rights
Where applicable under relevant law, users may request access, correction, export, deletion, restriction, objection, and consent withdrawal.
Children
CyberGuard is not intended for children. Minimum user age: [MINIMUM USER AGE].
Policy Changes
Version 2026.07.17-draft. Change summary: initial CyberGuard operational privacy template.